By submitting my Email address I confirm that I have read and accepted the Terms of Use and Declaration of Consent.

By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.

You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.

Also, what strength of encryption is needed externally, as well as any other requirements such as authentication, etc.?

Lastly, what exactly is considered confidential (clent ID/number, name)?

The HIPAA Security Rule, in its current proposed form, does not require internal e-mails on a wired network to be encrypted. E-mails are required to be encrypted if they go across an "open network" such as the Internet or even a wireless LAN. As of now, there is no minimum requirement for encryption strength. A common encryption strength is 168-bit (3DES), but 128-bit will usually suffice. Anything more may be overkill, anything less has been proven to be easily crackable. See Expert deconstructs the cracking of 64-bit key for more information on this subject.

Regarding authentication, the following is required:

data authentication -- mechanism that provides proof that data has not been altered or destroyed in an unauthorized manner

entity authentication -- mechanism that provides proof that an entity is who it claims to be

message authentication -- mechanism to ensure that a message received matches the message sent

Most, if not all, of these requirements can be met with third party mail gateway products and authentication systems from various vendors.

Regarding what is considered confidential, it basically boils down to any individually identifiable health information including SSN, name, address, medical record numbers, treatment history, etc. -- anything that can be used to indentify a patient. Stay tuned, however, the HIPAA Security Rule may be finalized at the end of December 2002 and might contain updates or changes to this information.

0 comments

Register

Login

Forgot your password?

Your password has been sent to:

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy